logo

Okta: Breach Affected All Customer Support Users

ID: f2e35e9c-cd66-5f0b-9719-c978728e4f35

STIX ID: report--f2e35e9c-cd66-5f0b-9719-c978728e4f35

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2023-11-29

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Okta disclosed that intruders accessed its customer support case management system in late September–October 2023, stealing authentication tokens for some customers (initially reported as files for 134 customers) and the names and email addresses of nearly all customer support system users; roughly 97% of exposed accounts contained only name and email, while about 3% included additional fields such as last login, username, phone number, SAML federation ID, company name, and job role. The company attributed the intrusion to a compromised service account credential that had been saved to an employee's personal Google account, highlighting elevated risk to Okta administrators and the potential for targeted phishing or account takeover if MFA is not enforced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.